← Back to CVE List
Vulnerability Intelligence Report
Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)

CVE-2026-58231

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.1
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-94 ↗CWE-94: Improper Control of Generation of Code

Affected Products & Versions

Vendor Product Affected Versions
SAP_SE SAP Commerce Cloud (Data Hub Adapter) COM_CLOUD 2211 (affected), 2211-JDK21 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Identity & Timeline

StatusPUBLISHED
Assigning AuthoritySAP SE · Vendor · Germany
Reserved2026-06-29T19:34:28
Published2026-08-11T10:21:29
Last Updated2026-08-12T03:59:57

LINK COPIED TO CLIPBOARD